Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000032

Опубликовано: 17 июл. 2017
Источник: debian

Описание

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed0.8.8b+dfsg-6package
cactifixed0.8.8a+dfsg-5+deb7u3wheezypackage

Примечания

  • MITRE will not reject the entry, but the issue is already covered by the

  • patch as for CVE-2014-4002. See discussion in

  • https://github.com/distributedweaknessfiling/DWF-CVE-Database/issues/27

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 8 лет назад

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

CVSS3: 6.1
nvd
больше 8 лет назад

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

CVSS3: 6.1
github
больше 3 лет назад

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.